Overview
Grades the security headers in a pasted HTTP response: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, clickjacking protection, Referrer-Policy, Permissions-Policy, the cross-origin isolation headers and cookie flags. Each finding comes with a concrete fix, and nothing is fetched, so you can check staging, internal or offline captures.
How It Works
Run curl -sI https://your-site, copy the response headers from the browser's Network tab, or paste curl -v output, then paste the text into the box. The tool reads the status line and headers, uses only the last response if you pasted a redirect chain, and shows a letter grade with a card for each check. Every card quotes the value found, explains the problem and lists the change to make. Suggested starting headers appear for anything missing, and the full report can be copied or downloaded.
Step-by-Step Usage Guide
- Capture the response headers with curl -sI, curl -v or the browser's Network tab and paste them in.
- Check the grade and work through the failing cards first, starting with Content-Security-Policy and HSTS.
- Apply the suggested headers in your web server, CDN or application, adjusting the CSP to the sources your pages really use.
- Capture the headers again and paste them in to confirm the changes took effect.
Technical Specifications & Standards
The grade is this tool's own scale, not an industry standard: points earned divided by points available. Content-Security-Policy carries the most weight, followed by HSTS and clickjacking protection. The CSP check reads directives the way browsers do. 'unsafe-inline' in script-src counts as a weakness only when no nonce, hash or 'strict-dynamic' is present, because those make modern browsers ignore it. With 'strict-dynamic' host and scheme sources are ignored too. default-src is the fallback for script-src and object-src, but base-uri and frame-ancestors have no fallback, so they are checked separately. Several CSP headers are all enforced together, and a Report-Only policy is reported as not enforcing anything. HSTS needs a positive max-age; 31536000 seconds (one year) is also the minimum for the browser preload list, which additionally requires includeSubDomains. X-Frame-Options accepts only DENY and SAMEORIGIN, since ALLOW-FROM is ignored by current browsers, and CSP frame-ancestors takes precedence where supported. Referrer-Policy lists are read as a fallback chain, so the last token the browser understands wins. Permissions-Policy must use structured syntax such as camera=(), not the old Feature-Policy quoting. COOP, COEP, CORP and cookies only affect the grade when they are present, because many sites are well protected without them. Cookies are judged on Secure, HttpOnly and SameSite, plus the rules for the __Host- and __Secure- prefixes. The tool cannot tell whether the response came over HTTPS, cannot see a CSP set in a meta tag, and only judges the one response you pasted; other paths and CDN edge nodes can send different headers.
Targeted Use Cases
- Reviewing a new deployment's headers before it goes live.
- Preparing evidence for a security questionnaire or penetration test follow-up.
- Checking that a CDN or reverse proxy is not stripping headers set by the application.
- Auditing the cookie flags on a session cookie after a framework upgrade.
Notes & Gotchas
- Roll out Content-Security-Policy in Report-Only mode first, then enforce it once the reports are clean.
- Raise the HSTS max-age in steps and add includeSubDomains only when every subdomain works over HTTPS.
- Check several pages, including login and API responses, because headers often differ by route.
- Remove version numbers from Server and X-Powered-By, since they help attackers and nobody else.
Frequently Asked Questions
Does the tool make requests to my site?
No. It only analyzes the text you paste, and nothing is fetched or uploaded. That also means it works for staging servers, intranets and headers saved from earlier.
Why did I lose points for a header that my site does not need?
The scored headers protect against common browser attacks and apply to most sites. The optional COOP, COEP and CORP headers and cookie checks only count when present, so leaving them out never lowers the grade.
My CSP has 'unsafe-inline' but no penalty was applied. Why?
When the same directive also has a nonce, a hash or 'strict-dynamic', current browsers ignore 'unsafe-inline', so it only acts as a fallback for very old browsers. The tool notes this instead of penalizing it.
Is an A here the same as an A on other scanners?
No. Each scanner uses its own weights and checks, so grades differ. Use this one to find concrete header fixes rather than to compare scores between tools.